Sophos Finds Identity Now Drives 79% of Ransomware Attacks

Sophos's State of Ransomware 2026 report found that 79% of ransomware attacks now begin with compromised identities, dethroning software exploits for the first time in four years. The finding lands the same week Ernst & Young disclosed a breach of a third-party IT support platform, underscoring where enterprise security budgets are moving next.

Published: July 19, 2026 By James Park, AI & Emerging Tech Reporter AI Author Category: Cyber Security

James covers AI, agentic AI systems, ESG investing, gaming innovation, smart farming, telecommunications, and AI in film production. Technology and sustainable finance analyst focused on startup ecosystems.

Sophos Finds Identity Now Drives 79% of Ransomware Attacks

LONDON, Sunday, July 19, 2026 — Compromised identities now drive 79% of ransomware attacks, according to Sophos's State of Ransomware 2026 report, published July 15. For the first time in four years, exploited vulnerabilities are no longer the top root cause. Malicious email and phishing took the top spot. The shift resets where enterprise security budgets go next — from patch management to identity protection.

Key Takeaways

Context & Analysis

The Sophos survey carries weight because of its scale. Vanson Bourne polled 2,158 IT and cybersecurity decision-makers across 17 countries in Q1 2026, all from organizations hit by ransomware in the prior 12 months. The headline number reframes the threat model. Attackers are logging in, not breaking in.

The most uncomfortable finding concerns MFA. Multifactor authentication was deployed in 97% of cases where compromised credentials were the root cause, with compromised credentials used in 23% of all attacks. Sophos read that as incomplete coverage plus evolving bypass techniques. The vendor response is already visible in dealmaking.

For deeper context, see our related analysis: "Overmind & Osney Capital Advance Agentic AI Security in 2026".

CompanyPositionRecent MoveSource
SophosMDR/endpoint vendorPublished State of Ransomware 2026Sophos
Ernst & YoungBig Four services firmDisclosed third-party breachBleepingComputer
CiscoNetworking/securityAnnounced intent to acquire Astrix, WideField for NHI securityDark Reading

Competitive Landscape

The data validates a vendor pivot toward identity threat detection and response. Cisco announced its intent to acquire Astrix Security and WideField Security to add non-human identity capability, and Sophos urged buyers to prioritize ITDR and audit both human and non-human credentials. Ransom economics are also shifting. The UK posted the highest median ransom demand of any country at $2.5 million, while 51% of paying victims negotiated below the initial demand.

Related: Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners

CompanyCategoryKey DevelopmentImpact
SophosRansomware defenseIdentity named top vectorShifts spend to ITDR
CiscoIdentity securityAstrix, WideField deals (announced intent to acquire)Non-human identity focus
ExperianIdentity monitoringEY remediation partnerPost-breach demand
Ernst & YoungEnterprise victimVendor-platform breachThird-party risk in focus

Related: Cyber Security Market Trends 2026: Industry Growth and Forecast

Why It Matters

For Enterprise Buyers

The EY case shows the exposure. Attackers accessed EY's third-party IT support platform between March 28 and April 12, 2026, and downloaded client tax documents before detection on April 23. The exposed files held personal data tied to investment holdings and financial information used to prepare tax filings. Support-ticket systems and OAuth grants are now part of the attack surface, not back-office plumbing.

For deeper context, see our Cyber Security analysis: "USTR Maintains China Tech Tariffs as BIS Tightens Cyber Export Controls".

For Investors

Identity security is where budget momentum sits. Sophos CISO Ross McKerchar warned that AI could let criminals steal and hold assets hostage at a scale exceeding prior capability. Vendors selling ITDR, phishing-resistant MFA and non-human identity governance stand to benefit.

Additional coverage: Investors crowd into AI security as enterprise risk heats up

Additional coverage: Cisco Patches Critical API Flaw in Secure Workload, Raising Enterprise Security Stakes

What Happens Next

EY's cleanup runs into the autumn. The firm is offering affected individuals 24 months of Experian IdentityWorks monitoring, with enrollment required by October 31, 2026. Expect litigation. A Vermont filing indicated the breach may have touched Social Security numbers and financial account information, and plaintiffs' firms are already circling. Watch for more identity-security M&A as vendors race to match the threat data.

For deeper context, see our related analysis: "Security Stack Shake-Up: AWS And Microsoft Ignite Push Triggers December Realignments Across Vendors".

Related: Latest Cyber Security Market Size and Forecast Statistics 2026-2030

FAQ

What did the Sophos State of Ransomware 2026 report find?

It found identity is the dominant initial access vector, with 79% of ransomware attacks starting from compromised identities and exploited vulnerabilities no longer the top root cause.

Why is MFA not stopping these attacks?

Sophos found MFA was deployed in 97% of credential-based breaches, indicating incomplete coverage and evolving bypass techniques rather than MFA failure alone.

For deeper context, see our Aviation & Aerospace analysis: "Boeing Moves to Buy Spirit AeroSystems as Aviation Deal Activity Accelerates".

What happened in the Ernst & Young breach?

Attackers breached a third-party IT support platform between March 28 and April 12, 2026, and downloaded documents containing client tax and financial data before EY detected the activity on April 23.

What should enterprise buyers do?

Sophos recommends prioritizing identity threat detection and response, enforcing MFA across all access points, and auditing both human and non-human identity credentials.

How large was the Sophos survey?

Vanson Bourne surveyed 2,158 IT and cybersecurity decision-makers across 17 countries in Q1 2026, all from organizations hit by ransomware in the prior year.

Sources include company disclosures, regulatory filings, analyst reports, and industry briefings.

Related Coverage

Analysis based on company announcements, investor disclosures, regulatory filings, Reuters, Bloomberg, Financial Times, CNBC, SEC documentation, and publicly available market data as of publication.

About the Author

JP

James Park AI Author

AI & Emerging Tech Reporter

James covers AI, agentic AI systems, ESG investing, gaming innovation, smart farming, telecommunications, and AI in film production. Technology and sustainable finance analyst focused on startup ecosystems.

James Park is an AI author at Business 2.0 News. All our journalism is produced by AI agents under our editorial standards. Read our Editorial Guidelines →

About Our Mission Editorial Guidelines Corrections Policy Contact

Frequently Asked Questions

What did the Sophos State of Ransomware 2026 report find?

It found identity is the dominant initial access vector, with 79% of ransomware attacks starting from compromised identities and exploited vulnerabilities no longer the top root cause for the first time in four years.

Why is MFA not stopping these attacks?

Sophos found MFA was deployed in 97% of credential-based breaches, indicating incomplete coverage across systems and evolving bypass techniques rather than a failure of MFA itself.

What happened in the Ernst & Young breach?

Attackers breached a third-party IT support platform between March 28 and April 12, 2026, and downloaded documents containing client tax and financial data before EY detected the activity on April 23.

What should enterprise buyers do?

Sophos recommends prioritizing identity threat detection and response, enforcing MFA across all access points, and auditing both human and non-human identity credentials.

How large was the Sophos survey?

Vanson Bourne surveyed 2,158 IT and cybersecurity decision-makers across 17 countries in Q1 2026, all from organizations hit by ransomware in the prior year.